OSX00165 - Securely configure /etc/sshd_config - Prevent root login

Information

Prevent logging in as root through SSH. This should be set for all SSH methods of authenticating.

Solution

1. Open a terminal session and enter the command- sudo pico /etc/sshd_config
2. Edit the value PermitRootLogin and set it to No.
3. Save the file

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx10.5_v1r2_stig_20110729.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(4), CAT|II, Rule-ID|SV-31343r1_rule, STIG-ID|OSX00165, Vuln-ID|V-25273

Plugin: Unix

Control ID: 1628a4334c55aed0cb6cbf6146a158097aac06ae1a66fe383b443e78bcb0fd98